Vulnerabilities > CVE-2023-1169 - Unspecified vulnerability in Ooohboi Steroids for Elementor Project Ooohboi Steroids for Elementor

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE

Summary

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.

Vulnerable Configurations

Part Description Count
Application
Ooohboi_Steroids_For_Elementor_Project
30